Cloudflare Workers caps PBKDF2 at 100,000 iterations. Node doesn't. wrangler dev doesn't. So a local benchmark and a full end-to-end migration test both passed — and production broke in a way nobody could see.
3 comments
It dates back to when Workers only supported 50ms CPU time limits. Back then 100k iterations was enough to exceed the 50ms budget.
Now that the limit is 5 minutes this is pretty silly, but since PBKDF2 is considered obsolete and not often used in new code, I guess fixing it never really came up.
I would accept a PR to increase the constant to 1M, or higher with a good argument (but most recommendations I see for iteration count are <1M). Constant defined here:
https://github.com/cloudflare/workerd/blob/main/src/workerd/...
Which is to say... yes... I would probably use Argon2id if I could, but I can't (I mean... not in all projects) so fixing this bug is appreciated.
Read the full thread on Hacker News →
Related stories
- The Verge · 0 points · 5 days ago
- DEV Community · 0 points · 8 days ago
- Native Rust on Cloudflare Workers via Emscriptenblog.cloudflare.comHacker News · 2 points · 3 days ago
- Cloudflare Python Workers are now generally availablesimonwillison.netHacker News · 1 points · 7 days ago
- DEV Community · 1 points · 2 days ago
- Ars Technica · 0 points · 8 days ago